890
VMScore

CVE-2017-17458

Published: 07/12/2017 Updated: 31/07/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

In Mercurial prior to 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construction of such repositories, but they can be created programmatically.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mercurial mercurial

debian debian linux 7.0

debian debian linux 8.0

Vendor Advisories

It was found that mercurial was vulnerable to cross repositories modification A specially crafted mercurial repository could trigger arbitrary commands on a client during commands such as clone or update ...